Topic Privacy & Incident Response
When privacy laws collide with a real incident.
State privacy laws, breach notification timelines, and incident response playbooks — for the team that has to decide what to disclose, to whom, and by when. Aligned with NIST SP 800-61, state breach laws, and federal incident reporting.
◆ CCPA · CPRA · state privacy laws · NIST SP 800-61 · federal breach rules
◆ What you'll find here
Privacy and incident response, treated as one program.
◆ 01
State privacy laws
CCPA, CPRA, Colorado, Connecticut, Texas, and every state law that follows the same pattern. The obligations, the timelines, and what your privacy program actually has to do.
◆ 02
Breach notification
All 50 state breach laws plus federal sector rules (HIPAA, GLBA, SEC cyber, banking incident reporting). Decision trees, notification templates, and the timelines that actually trigger reporting.
◆ 03
IR playbooks
Ransomware, BEC, third-party breach, insider, lost device — the eight playbook patterns that cover most real incidents. Built on NIST SP 800-61 and what actually happens in the room.
◆ Privacy & incident response templates
Tools for privacy + IR teams.
Decision trees, notification templates, IR runbooks, and the evidence you need to show regulators and bank partners.
Data Privacy Compliance Kit
Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.
Incident Response & Breach Notification Kit
Step-by-step incident response playbooks and breach notification templates for all 50 states.
82+
Privacy & IR articles
50
State breach laws covered
US
CCPA · CPRA · NIST SP 800-61 · sector rules
◆ Latest analysis
From the journal.
Data Privacy
Global Privacy Control for Financial Services: A State-by-State Scope Test
A practical Global Privacy Control guide for financial services: state scope, GLBA exemptions, signal handling, testing, and evidence.
Data Privacy
California Just Fined a Data Broker $116K for Making Opt-Out Too Hard. Your Fintech's Data Practices Are Next.
CalPrivacy ordered LocateSmarter to pay $116,490 over registration and opt-out violations, then fined Cybba $52,400 two days later.
Data Privacy
Washington MHMDA for Fintech: The GLBA Data Exemption and CPA Enforcement
Washington's My Health My Data Act has a data-level GLBA exemption and uses the Consumer Protection Act for public and private enforcement.
Data Privacy
Location Data Enforcement in 2026: Kochava, GM/OnStar, and Allstate/Arity
Separate the 2026 Kochava and GM orders, California's GM settlement, Texas's Allstate/Arity suit, and private location-data litigation.
Data Privacy
NYDFS's First 2026 Cybersecurity Fine Wasn't About the MOVEit Hack. It Was About What Happened After.
On April 29, 2026, NYDFS issued a $2.25 million consent order against Delta Dental of New York—its first 2026 cybersecurity enforcement action. The underlying breach was a 2023 MOVEit zero-day. The violations were late notification, inadequate data disposal, and insufficient incident response plan detail. And the consent order bars insurance reimbursement. Here's what the enforcement record tells your program.
Incident Response
CIRCIA Status in August 2026: No Final Rule and No Current 72-Hour Duty
CIRCIA remains in rulemaking. Separate its proposed 72- and 24-hour reports from the banking agencies' existing 36-hour notification rule.